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MEMORANDUM FOR: Director, National Foreign Assessment Center 

Deputy Director for Administration 
Deputy Director for Science and Technology 
Deputy Director for Operations 

FROM: James H. McDonald 

Director of Logistics 


SUBJECT: 


Implementation of Task Force Recommendations 


REFERENCE: 


Industrial Contracts and Industrial Security 
Final Report dated February 1978 


1. The DCI's Task Force on Industrial Contracting and 
Industrial Security set forth a number of recommendations 
designed to strengthen the security aspects of Agency con- 
tracting procedures. Policy guidance on implementing the 
Task Force recommendations, given particular emphasis by the 
DCI, has been issued to procurement personnel in the attached 
OL Procurement Notes, also listed below: 

PN #103 - Industrial Contract Security - Determina- 
tion of Responsibility 

PN #115 - Security Performance Incentive in Incen- 
tive/Award Fee Contracts 

PN #116 - Enforcement of Security Provisions in 
Agency Contracts 

PN #117 - Security Requirements in Requests for 
Proposals. 


2. These Procurement Notes primarily address the Con- 
tracting Officer's responsibilities. Their effective imple- 
mentation, however, depends , on large part, on close cooperation 
between procurement, technical, and security personnel involved 
in contracting activities. Your assistance is, therefore, requested 
in disseminating the attached Procurement Notes to appropriate 
technical officers within your command structure and in en- 
couraging their support for early implementation of these 
policies . 
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SUBJECT; Implementation of Task Force Recommendations 


3. Procurement Notes, in furtherance of several remaining 
Task Force recommendations, will be promulgated in the near 
future. Your assistance in this important matter will be 
greatly appreciated. 

STATINTL 


Att 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 103 


INDUSTRIAL C0NTR.\CT SECURITY - 
DETERMINATION OF RESPONSIBILITY 


Intel l"i(Tr.i7-\^ rnrT?^^F letter prepo.rod Ey the Director o£ Central 
intelligence (POI) for dissemination to selected Agency con- 
tiactors, concern was expressed regarding compliance with 
industrial contract security requirements. A^plea is mace in 
that same letter for higher levels of consciousnos s and ' iMoher 
standards of performance with regard to security aspects "of 
Agency contracts. In this regard the DC! lias stated: 


"I have directed other initiatives as well, 
including the require:nent tliat a contractor's 
security record and posture be taken into account 
wnen it comes to the award of new contracts and 
more effective provisions within our contracts with 
respect to security, 


Contracting officers arc routinely required to ivake 

responsibility in accorciancc 
wiili Abl R 1“.>02 wliicn states that; "Purchases shall be 'lade 
trom, and contracts shall be awarded to, responsible contrac- 
tors only.'' To meet the minimum standards for an affirmative 
determination of responsibility a contractor must; 


a. Have adequate financial resources, cr the 
ability to obtain such resources as required durinc- 
performance of the contract [see De£cn.s7 Contract 
Financing Regulations, Part 2, Appendix E, and any 
amendments _ thereto ; sec also 1-904.2 and 1-905.2; for 
SBA certificates of competency, see 1 -705.4) ; 

b. Be able to comply wirJi the -.■cquirec or pro - 
posed pelivery or performance schedule, taking into 
consideration all existing business commitments, 
commercial as well as governmental (for SEA certif i - 
cates of competency, see l-7(i5.4); 


OL 7 .5 9.56 
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OPFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 103 


^c. liaA/'e a satisfactory reccrd of performance 
(contractors uiio are seriously deficient in current 
conti act p cr (: 0 riiuinc s , when tiie number of contracts 
and the_ extent of deficiency of each are considered, 

.sJicil.L, in the nbboncG of ovioonce to tlic contrary or 
circumstances properly beyond tiie control of the 
contractor, be presumed to be unable to meet this 
lequiicment) . Past unsat is factor)' performance, duo 
to failure co appl)^ necessary tenacity or pers8Vcra.nce 
to do an acceptable job, shall be sufficient to justify 
a finding of nonresponsibility. (In the case of small 
business concerns, see 1 - 7 0 5 . 4 (c) O'i) and 1 - 905.2); 

d. Have a satisfactory record of integrity 

(in the case of a small business concern, sei'' 1 - 70 5 a 
(c)(vi)); and, 

e. Be otherwise qualified and eligible to receive 
an award under ai^plicable lav/s and regulations, e 
Section XII, Parts 6 and 8 (in the case of ' a sriili'” ’ 
business concern, see 1- 70 5 . 4 (c) (v) j . 

3. Compliance with applicable security requirements, 
u’hether imposed by statute, regulation or embodied In conti'cic'*' 
terms and conditions, is a critical element in performance of 
contracts for this Agency. As such, contracting officers are 
diiected to review existing procedures v.diich require coordina- 
tion with a cognizant representative of tlic Office of Sccurity 
prior to execution of any contract which involves classified 
inf o 1 ii)at i 0 , 1 . Ihey ma.y not execute any contract involving 
clasyfied Information (work, reports, association ]iardw.are, 
etc.) V'/ithout certification from their cognizant security 
1 epi 0 s ent a t iv e rcga.rding tlic contractor's current security 
capability as well as the contractor's record of past performance 
in complying wJ tli security ]'cquiromcnts . Approval by the cconi- 
zant security representative cf contractor responsibility in" 
the ;p'ea ot complianco with industrial contract sccuri.ty 
requirements must be evidenced by his signature o’.i Forni 1218, 
Irocuromont Justification and Routing Shc!Ot, in accordance 
with existing procedures. 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 105 


4. New, stronger security clauses for inclusion in 
Agency contracts arc in process and will be promulgated 
upon completion. 


STATINTL 

STATINTL 



J am e s II . M c D o n a 1 d. 
Director of Logistics 


CONCUR: 



■'Date 





STATINTL 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 115 
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SECURITY PERFORMANCE INCENTIVE 
IN INCENTIVE/TONARP Fee irONTRACfS 


1. The Task Force on Industrial Security and Industrial 
Contracting recommended in its interim report that incentive/ 
award fee type contracts include security performance, along 
witli other performance requirements, as a basis for foe deter 
mination. The DCI has approved this concept and has noted 
that the value of products and/or services required through 
industrial contracts may be diminished or negated if security 
is compromised. This procurement note is issued to provide 
policy guidance on implementation of the Task Force recom- 
mendation. 

2. Effective this date, procurement personnel are di- 
rected to incorporate security performance criteria in award 
fee and combination inccntivc/award fee contracts. This poll 
is not applicable to other incentive fee arrangements. The 
purpose of establishing security performance criteria as one 
determinant of award foe is to provide a meaningful incentive 
to contractors, balanced against the primary contract objec- 
tive of obtaining products and/or services. Security per- 
formance criteria shall, therefo re, be tailored to the unique 
requirements of each contract action, and no standard pre- 
determined weight shall be assigned to this performance fac- 
tor. The weight given to security performance criteria shoul 
be based on the sensitivity of the contemplated effort, and a 
determination of the relative importance of security versus 
other selected performance factors. Generally, there wi]l be 
a direct correlation between the sensitivity of the contem- 
plated effort and the weight assigned to security performance 
criteria . 

5. It is emphasized that this rcquircmenl' is closely 
linked to the prenegotiation activities oi' (a) lu’oposal 
solicitation in which contemplated security requirements arc 
established and the contractor's plan for satisfying tl^ose 
requirements is requested, and (b) proposal evaluation during 
wliich the contractor's security plan will be assessed, and 
in competitive situations rated as a part of the overall 
source selection process. 


I : j fc Uv i * I 






V- V; 




OL 8 2755 


Approved For Release 2002/01/15 : CIA-RDP81-00142R000600090014-5 



/• . 



OPFICB OF LOGISTICS 
PROCUREMENT NOTE NO. 115 


4. Security performance criteria shall be established in 
a manner similar to other selected performance criteria and 
will result in a unilateral determination by the Government not 
subject to the contract disputes clause. In selecting these 
criteria, consideration should be given to security require- 
ments established prior to proposal solicitation, the con- 
tractor's proposed security plan and the Government's evalua- 
tion thereof, and the security requircmeiits to l^e incorporated 
in the anticipated contract. Examples of subelements that 
might be used to define security performance include: timely 
submission of contractor personnel security approval requests; 
proper handling and processing of classified contract data and 
documents; contractor's responsiveness to instructions and 
requirements of Agency security representatives; contractor 
compliance v;ith security requirements unique to the contract; 
contractor performance regarding proper classification of 
contract documents and data; promptness and diligence in 
correcting deficiencies noted during contractor security 
inspections; contractor's success in avoidiiig compromise of 
classified information; contractor's record regarding reported 
security violations; and contractor's overall record of 
compliance with established Agency security procedures and 
directives. 


STATINTL 


5. It is recognised that this policy injects a nev; 
evaluation element into the determination of award fees 
under Agency contracts and that careful planning will be 
required for its successful implementation. Accordingly, 
attention must be given to this requirement early in the 
procurement cycle. Procurement personnel shall iae respon- 
sible for implementing this policy and necessary coordination 
with technical personnel involved in evaluating contractor 
performance and performing award fee evaluations. Compliance 
with the requirements of this Procurement Note will be 
reviewed during scheduled inspections of decentralized 
contract teams and as a part of reviews by the Agency 
Contract Review Board. 


//.; a me s TT ivic i.v on J. a 
./Director of Logistics 
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OFFICE OF LOGISTICS ^ 

PROCUREMENT NOTE NO. 116 1- JUL l978 


ENFORCEMENT OF SECURITY PROVISIONS 
IN AGENCY CONTRACTS 


The Task Force on Industrial Contracts and Industrial 
Security recommended and the DDCI has directed: 

"That the Director of Security be responsible 
for monitoring the security responsibilities of the 
contractor. The enforcement of contract terms, 
including those covering security performance, remain 
the responsibility of the contracting officer." 


"That remedies available in contract law be 
used as the primary means of enforcing contractor 
compliance with industrial security standards." 

these directions do not change procedures which 
have been used on a continuing basis for several years, we 
believe it is necessary to emphasize the importance of the 
respective roles of the contracting officer and his security 
representative in the enforcement of security provisions of 
our Agency contracts. 


STATINTL • . ^ 

Since the damaging matter , a multifaceted 

program has been under way in an attempt to shore up our 
industrial security program. For example, stronger security 
clauses are in process. Security manuals are being revised. 
Contracts are being incentivized to provide either reward 
or penalty for. contractor security performance. Contractors; 
are being inspected by teams from the Agency and security 
performance has been identified as a critical item in award 
of contracts. 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 116 


Admiral Turner, in a September 1977 letter to our 
contractors, has said: 

•'I want to make it clear that I regard security 
as being o£ central importance in the performance of 
contracts funded or administered by this Agency. 

Nearly all of the work under contract would be of 
lesser value, and much of it would be of little value 
if it could not be performed in a secure manner and 
protected against unauthorized disclosure, whether 
deliberate or inadvertent, which I have the statutory 
obligation to protect." 

Contractor compliance with industrial contract security 
requirements must be of greater concern to each of us involved 
in the procurement process than at any time in the past. Some 
contractors have very effective security programs and actively 
seek to improve them; most contractors need to effect higher 
standards. Overall security policy standards and the monitoring 
thereof are Office of Security responsibilities. Enforcement 
of security requirements are the responsibility of the contracting 
officer . 

Contracting officers are directed, in light of the DDCI 
direction, above, to again review and to maintain a working 
knowledge of the security requirements expressed in the General 
Provisions (Section A, Article 23} , Procurement Note numbers 
58, 103 and 115 as well as the appropriate security clauses of 
the contract schedule, and existing security procedures. Com- 
pliance with applicable security requirements, whether imposed 
by statute, regulation. General Provisions or embodied in 
contract terms and conditions, shall be strictly enforced. 

Contracting officers are again reminded that they may not 
execute any contract involving classified information (associa- 
tion, work, reports, hardware, etc.) v^ithout certification from 
their cognizant security representative regarding the contractor's 
current security capability as \\fell as the contractor's record 
of past performance in complying with security requirements. 



Director of Logistics 
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OFFICE OF LOGISTICS 

PROCUREMENT NOTE NO. 117 18 J'JL V.78 


SECURITY REQUIREMENTS IN REQUESTS FOR PROPOSALS 


1. The Task Force on Industrial Contracts and Industrial 
Security recommended in its interim report that "requests for 
proposals which anticipate classified contracts describe 
security requirements and require that the contractor include 
in his proposal his plan for satisfying those requirements." 

The purpose of this Procurement Note is to implement the above 
recommendation. 

2. While it has been common practice to describe the 
security requirements of a contemplated contract in Agency 
RFP's, potential offerors have not generally been instructed 

to submit a formal plan for meeting these requirements. Effec- 
tive this date, procurement personnel are directed to include 
a requirement in RFP's for offerors to submit a plan for 
satisfying security requirements of the anticipated contract 
in their proposals. The size and complexity of the offeror's 
security plan will depend upon the magnitude of security 
requirements in the RFP. In some cases, one paragraph in the 
offeror's proposal may suffice, while in others a multipart 
document may be necessary. In any event, the security plan 
should demonstrate that the offeror has a full comprehension 
of the security requirements and intends to comply with same. 

3. Logistics Instruction No. 45-30 dated 14 June 1978, 
a copy of which is attached, establishes the requirement for 
completion of a Contract Data Classification Guide (CDCG) 
prior to execution of all contracts exceeding $10,000 in value 
where work, reports, association, hardware, or production 
equipment is determined to be classified. The CDCG will be 
incorporated in such contracts by reference. The Contracting 
Officer's Technical Representative is responsible for completion 
of the CDCG; hovsrever, his determinations of security classifi- 
cation will very likely involve coordination and discussions 
with the Contracting Officer and cognizant Industrial Security 
Officer. Procurement personnel should encourage COTR's to 

make CDCG security determinations prior to solicitation of 
proposals as this document, properly completed, can then be 
used as a basis for establishing security requirements in the 
RFP. 
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OFFICE OF LOGISTICS 
PROCUREMENT NOTE NO. 117 


4. A repres 
addressed in offe 
Contract security 
proposed security 
circumstances of 
attached listing 
regarding matters 
plans. 


entative listing of matters that should be 
ror'sproposed security plans is attached, 
requirements and criteria for evaluating 
plans should be tailored to the unique 
each contract action. Therefore, the 
is intended to provide only general guidance 
to be covered in offeror's proposed security 


Procurement personnel will be responsible for 

effecting necessary coordination 
with technical and security personnel. Compliance with the 

Procurement Note will be reviewed during 
scheduled inspections of decentralized contract teams and 

Boa^d'^^^ ^ reviews by the Agency Contract Review 



STATINTL 


H. McDonald 
of Logistics 


Att 
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LOGISTICS INSTRUCTION NO. 
LI 45-50 


LI 45-3} 
LOGISTICS 
21 June 1973 


SUBJECT; Industrinl Contract Security - 

Contract Data Classification Guide 

REFERENCES: a. Class if ied Contract Security 

b. Office of Logistics Procurenent Note No. 105 
Industrial Contract Security 


1. PURPOSE 

This instruction supplements existing procedures 7 overninc^ th- 
Agency s classified procurement activities which will identic 
VMth more specificity the security classification of the ele-' 
ments and products thereof. 

2. POLICY 


a. Adherence to the 
contractual 


Security is 
tracts for 


security policy and standards for indus 
arrangements establisned by the Director 
a critical element in the administration 


c. 1 


this Agency. 


0 

of 


con- 


ihe Contract Data Classification Guide (CDCG)=^ 
pleted on all procurement actions for materiel 


anticipated to exceed 510,000 and where 


association, hardware, or production 
to be classified. 


the 
equipni 


will be com- 
and/or servic 


v.'ork , 
int is 


reports , 
deter;nineu 


c. A^copy of the completed CDCG will accompany the contract when 
1 c IS j-orwaided to tne contractor foz' signatui*e I wi’ 1 
•serve to notify the contractor of thc_ sclarity Aassifilat ;on 

v;ith the contract. It \'ill 
all official copies of the con- 


of the 


become a 
tract . 


key 


clecients ass 
permanent nart 


The contract clause incorpo 
state that this is no 
CDCG may be a part of 
ance 


518 


par 

for contractor liandling 


he CDCG should cloarl\' 
an all-inclusive list. Although tr.e 
lIic coi'.tract, it only serves as guid- 
of classified m.aterials. 


* To be reproduced locally 
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LOGISTICS INSTRUCTION NO. L] 

LI45~^Q inr 


Material produced under the contract and not specifically 
covered by the CDCG will still recjuire the contractor to 
seek Agency guidance regarding its handling. 

3. RESPONSIBILITIES 


Effective inniiediately , Contracting Officers v.'ill not execute 
any contract of which any aspect is classified without a 
properly executed CDCG, 

The CDCG will be corapleted by the Contracting Officer's 
technical Representative and provided the Contracting Officer 
as an attachment to the Recjuest for Procurement Services 
(Form No, 2420) or the Requisition for Materiel and/or 
Services (Form No. 8S) as appropriate. 


STATINTL 


-Attachment 
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(ENTER APPROPRIATE CLASSIFICATION OF DATA OPPOSITE EACH ITEM BELOW) 


CLASSIFICATION 


CONTRACT NO. 


(CONF-SECRET-TS -OTHER) 


1. GOVERNMENT FURNISHED DATA: 

A. Contract 

B. Statement of Work 

C. Technical Information 

D. Specifications 

E. Drawings 

F. Graphics 

G. Computer Software 

H. Communication Security (COMSEC) Material 

I. Other (attach sheet for additional Data items) 


II. CONTRACTOR PRODUCED DATA: 


A. Reports 

1. Preliminary 

2 . Interim 

3 . Final 

4 • Manuals 

5. Drawings 

6. Graphics 

7. Computer Software 

8. Other (attach sheet for additional Data items)' 

B. Hardware: (identify and note if sight sensitive) 

1 . Component 

2 . System 

3. Sub-system 

4 . Breadboards 

5. Prototypes 

6. Engineering Models 

7. Other (attach sheet for additional Data items) 


III. CRITICAL SECURITY ELEMENTS OF PROCUREMENT: (Statement) 


Approved For Release 2002/01/15 : CIA-RDP81-00142R000600090014-5 


Approved For Release 2002/01/15 : CIA-RDP81-00142R000600090014-5 


Items Typically Covered in Offeror's Security Plans 


1. Introduction/Objectives 

2. Security Organization 

a. Key Personnel 

b. Guard Force 

c. Fire/Safety Protection 

3. Personnel Security 

a. Personnel Screening 

b. Access Processing 

c. Security Questionnaire 

d. Security Training/Education 

4. Facility Security 

a. Plan Protection 

b. Project/Program Work Area 

c. Personnel Identification 

d. Visitor Control 

5. Contracts and Finance 

a. General 

b. Job Authorizations 

c . Vouchers 

d. Audits 

6. Material Procurement 

a. Routine Unclassified Procurement 

b. Special Unclassified Procurement 

c. Classified Procurement 

d. Subcontract Security 

7. Automatic Data Processing 

a. General 

b. Storage, Protection and Control 

c. Keypunch Operations 

d. Library 

e. Vendor Service Technicians/Maintenance Log 

f. Audit Trail 

g. Subcontracting 

h. Emergency Plan/System Crash/Compromise 
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8. Communications Security 

a. Sterile Post Office Boxes 

b. Sterile Telephones 

9. Emergency Plans 

a. Fire Response 

b. Civil Disorders 
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